Show filters
386 Total Results
Displaying 191-200 of 386
Sort by:
Attacker Value
Unknown

CVE-2023-1774

Disclosure Date: March 31, 2023 (last updated February 24, 2025)
When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
Attacker Value
Unknown

CVE-2023-1562

Disclosure Date: March 22, 2023 (last updated February 24, 2025)
Mattermost fails to check the "Show Full Name" setting when rendering the result for the /plugins/focalboard/api/v2/users API call, allowing an attacker to learn the full name of a board owner.
Attacker Value
Unknown

CVE-2023-1421

Disclosure Date: March 15, 2023 (last updated February 24, 2025)
A reflected cross-site scripting vulnerability in the OAuth flow completion endpoints in Mattermost allows an attacker to send AJAX requests on behalf of the victim via sharing a crafted link with a malicious state parameter.
Attacker Value
Unknown

CVE-2023-27266

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the /api/v4/users/me/teams API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
Attacker Value
Unknown

CVE-2023-27265

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
Mattermost fails to honor the ShowEmailAddress setting when constructing a response to the "Regenerate Invite Id" API endpoint, allowing an attacker with team admin privileges to learn the team owner's email address in the response.
Attacker Value
Unknown

CVE-2023-27264

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
A missing permissions check in Mattermost Playbooks in Mattermost allows an attacker to modify a playbook via the /plugins/playbooks/api/v0/playbooks/[playbookID] API.
Attacker Value
Unknown

CVE-2023-27263

Disclosure Date: February 27, 2023 (last updated February 24, 2025)
A missing permissions check in the /plugins/playbooks/api/v0/runs API in Mattermost allows an attacker to list and view playbooks belonging to a team they are not a member of.
Attacker Value
Unknown

CVE-2022-4045

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in the Mattermost allows an authenticated user to crash the server via multiple requests to one of the API endpoints which could fetch a large amount of data. 
Attacker Value
Unknown

CVE-2022-4019

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in the Mattermost Playbooks plugin allows an authenticated user to crash the server via multiple large requests to one of the Playbooks API endpoints.
Attacker Value
Unknown

CVE-2022-4044

Disclosure Date: November 23, 2022 (last updated February 24, 2025)
A denial-of-service vulnerability in Mattermost allows an authenticated user to crash the server via multiple large autoresponder messages.